Free Certification Practice Questions

MICROSOFT-AZ500

Loading…
Microsoft's AZ-500 You have an Azure subscription that contains a user named User1.You need to ensure that User1 can perform the following tasks:• Create groups.• Create access reviews for role-assignable groups.• Assign Azure AD roles to groups.The solution must use the principle of least privilege.Which role should you assign to User1?
#91
Microsoft's AZ-500 You have an Azure subscription that uses Azure AD Privileged Identity Management (PIM).A user named User1 is eligible for the Billing administrator role.You need to ensure that the role can only be used for a maximum of two hours.What should you do?
#92
Microsoft's AZ-500 You have an Azure subscription that contains a user named User1 and a storage account that hosts a blob container named blob1.You need to grant User1 access to blob1. The solution must ensure that the access expires after six days.What should you use?
#93
Microsoft's AZ-500 You have an Azure subscription linked to an Azure AD tenant named contoso.com. Contoso.com contains a user named User1 and an Azure web app named App1.You plan to enable User1 to perform the following tasks:• Configure contoso.com to use Microsoft Entra Verified ID.• Register App1 in contoso.com.You need to identify which roles to assign to User1. The solution must use the principle of least privilege.Which two roles should you identify? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point. E. User Administrator
#94
Microsoft's AZ-500 You have an Azure AD tenant.You plan to implement an authentication solution to meet the following requirements:• Require number matching.• Display the geographical location when signing in.Which authentication method should you include in the solution?
#95
Microsoft's AZ-500 Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure AD tenant.You plan to implement single sign-on (SSO) for Azure AD resources.You need to configure an Intranet Zone setting for all users by using a Group Policy Object (GPO).Which setting should you configure?
#96
Microsoft's AZ-500 You have an Azure AD tenant.You need to ensure that users cannot create passwords containing a variation of the word contoso.What should you configure? E. Azure AD Identity Protection
#97
Microsoft's AZ-500 You have a Microsoft Entra tenant named contoso.com.You plan to collaborate with a partner organization that has a Microsoft Entra tenant named fabrikam.com.Fabrikam.com uses the following identity providers:• Google Cloud Platform (GCP)• Microsoft accounts• Microsoft Entra IDYou need to configure the Cross-tenant access settings for B2B collaboration.Which identity providers support cross-tenant access?
#98
Microsoft's AZ-500 You have a Microsoft Entra tenant named contoso.com.You have a partner company that has a Microsoft Entra tenant named fabrikam.com.You need to ensure that when a user in fabrikam.com attempts to access the resources in contoso.com, the user only receives a single Microsoft Entra Multi-Factor Authentication (MFA) prompt. The solution must minimize administrative effort.What should you do?
#99
Microsoft's AZ-500 You have a Microsoft Entra tenant that uses Microsoft Entra Permissions Management and contains the accounts shown in the following table:Which accounts will be listed as assigned to highly privileged roles on the Azure AD insights tab in the Entra Permissions Management portal? E. Admin2, Admin3, and Admin4 only F. Admin1, Admin2, Admin3, and Admin4
#100
Microsoft's AZ-500 You have an Azure subscription that contains a user named User1 and an Azure Container Registry named ContReg1.You enable content trust for ContReg1.You need to ensure that User1 can create trusted images in ContReg1. The solution must use the principle of least privilege.Which two roles should you assign to User1? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point. E. AcrQuarantineWriter
#101
Microsoft's AZ-500 You have an Azure Container Registry named ContReg1 that contains a container image named image1.You enable content trust for ContReg1.After content trust is enabled, you push two images to ContReg1 as shown in the following table.Which images are trusted images?
#102
Microsoft's AZ-500 You have an Azure subscription that contains the virtual machines shown in the following table.All the virtual networks are peered.You deploy Azure Bastion to VNET2.Which virtual machines can be protected by the bastion host?
#103
Microsoft's AZ-500 You have Azure Resource Manager templates that you use to deploy Azure virtual machines.You need to disable unused Windows features automatically as instances of the virtual machines are provisioned.What should you use?
#104
Microsoft's AZ-500 You have an Azure subscription named Sub1. Sub1 contains a virtual network named VNet1 that contains one subnet named Subnet1.Subnet1 contains an Azure virtual machine named VM1 that runs Ubuntu Server 18.04.You create a service endpoint for Microsoft.Storage in Subnet1.You need to ensure that when you deploy Docker containers to VM1, the containers can access Azure Storage resources by using the service endpoint.What should you do on VM1 before you deploy the container?
#105
Microsoft's AZ-500 You have Azure Resource Manager templates that you use to deploy Azure virtual machines.You need to disable unused Windows features automatically as instances of the virtual machines are provisioned.What should you use?
#106
Microsoft's AZ-500 You are configuring an Azure Kubernetes Service (AKS) cluster that will connect to an Azure Container Registry.You need to use the auto-generated service principal to authenticate to the Azure Container Registry.What should you create?
#107
Microsoft's AZ-500 You have an Azure subscription that contains the Azure virtual machines shown in the following table.You create an MDM Security Baseline profile named Profile1.You need to identify to which virtual machines Profile1 can be applied.Which virtual machines should you identify?
#108
Microsoft's AZ-500 You have Azure Resource Manager templates that you use to deploy Azure virtual machines.You need to disable unused Windows features automatically as instances of the virtual machines are provisioned.What should you use?
#109
Microsoft's AZ-500 You have an Azure virtual machine named VM1.From Microsoft Defender for Cloud, you get the following high-severity recommendation: `Install endpoint protection solutions on virtual machine`.You need to resolve the issue causing the high-severity recommendation.What should you do?
#110
Microsoft's AZ-500 You have an Azure subscription that contains a virtual network. The virtual network contains the subnets shown in the following table.The subscription contains the virtual machines shown in the following table.You enable just in time (JIT) VM access for all the virtual machines.You need to identify which virtual machines are protected by JIT.Which virtual machines should you identify?
#111
Microsoft's AZ-500 You have Azure Resource Manager templates that you use to deploy Azure virtual machines.You need to disable unused Windows features automatically as instances of the virtual machines are provisioned.What should you use?
#112
Microsoft's AZ-500 You have an Azure Container Registry named Registry1.From Azure Security Center, you enable Azure Container Registry vulnerability scanning of the images in Registry1.You perform the following actions:✑ Push a Windows image named Image1 to Registry1.✑ Push a Linux image named Image2 to Registry1.✑ Push a Windows image named Image3 to Registry1.✑ Modify Image1 and push the new image as Image4 to Registry1.Modify Image2 and push the new image as Image5 to Registry1.Which two images will be scanned for vulnerabilities? Each correct answer presents a complete solution.NOTE: Each correct selection is worth one point. E. Image5
#113
Microsoft's AZ-500 You have the Azure virtual machines shown in the following table.You create an Azure Log Analytics workspace named Analytics1 in RG1 in the East US region.Which virtual machines can be enrolled in Analytics1?
#114
Microsoft's AZ-500 You are testing an Azure Kubernetes Service (AKS) cluster. The cluster is configured as shown in the exhibit. (Click the Exhibit tab.)You plan to deploy the cluster to production. You disable HTTP application routing.You need to implement application routing that will provide reverse proxy and TLS termination for AKS services by using a single IP address.What should you do?
#115
Microsoft's AZ-500 Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an Azure subscription. The subscription contains 50 virtual machines that run Windows Server 2012 R2 or Windows Server 2016.You need to deploy Microsoft Antimalware to the virtual machines.Solution: You add an extension to each virtual machine.Does this meet the goal?
#116
Microsoft's AZ-500 Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an Azure subscription. The subscription contains 50 virtual machines that run Windows Server 2012 R2 or Windows Server 2016.You need to deploy Microsoft Antimalware to the virtual machines.Solution: You connect to each virtual machine and add a Windows feature.Does this meet the goal?
#117
Microsoft's AZ-500 You have an Azure Active Directory (Azure AD) tenant named Contoso.com and an Azure Kubernetes Service (AKS) cluster AKS1.You discover that AKS1 cannot be accessed by using accounts from Contoso.com.You need to ensure AKS1 can be accessed by using accounts from Contoso.com. The solution must minimize administrative effort.What should you do first?
#118
Microsoft's AZ-500 You have an Azure subscription that contains an Azure Container Registry named Registry1. Microsoft Defender for Cloud is enabled in the subscription.You upload several container images to Registry1.You discover that vulnerability security scans were not performed.You need to ensure that the container images are scanned for vulnerabilities when they are uploaded to Registry1.What should you do?
#119
Microsoft's AZ-500 From Azure Security Center, you create a custom alert rule.You need to configure which users will receive an email message when the alert is triggered.What should you do?
#120